Production Cutover Command Center

Dwellmark production readiness

A secret-safe launch cockpit for Vercel, Supabase, private storage, tenant boundaries, advisor access, privacy controls, production smoke, demo-mode separation, and billing deferral.

Blocked44%blocked
Environmentproduction
Required tables14
Private buckets2
Prod services32/32
CheckedSep 10, 2026, 3:27 PM

Next Action

Resolve Supabase Auth reachability before login rollout.

No secret values are returned by this endpoint.

Production Service Cutover

Production service namespace is ready for controlled authenticated cutover; keep demo routes separate.

ready
21Database-backed19Tenant-scoped8Storage-backed32Demo-separated15Audit-required21Session-gated
Database-backed dashboard summary

/api/dashboard

Demo: /api/dashboard/demo
DBSessionTenantStorageAudit optionalDemoSecret-saferead
ready
Database-backed ledger and day rows

/api/ledger/days

Demo: /api/ledger/demo/days
DBSessionTenantStorageAudit optionalDemoSecret-saferead
ready
Manual correction writes

/api/ledger/corrections

Production-only route
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Evidence vault inventory and private storage

/api/evidence/vault/records

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-saferead
ready
Evidence signed upload URL

/api/evidence/vault/uploads

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-safewrite
ready
Evidence upload completion

/api/evidence/vault/uploads/complete

Production-only route
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Evidence signed download URL

/api/evidence/vault/downloads

Production-only route
DBSessionTenantStorageAuditDemoSecret-saferead
ready
Evidence record-backed signed download

/api/evidence/vault/downloads/by-record

Production-only route
DBSessionTenantStorageAuditDemoSecret-saferead
ready
Evidence lifecycle readiness aggregate

/api/evidence/readiness

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Mobile capture production ingestion

/api/mobile/capture

Demo: /api/mobile/demo/capture
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Household and business operations

/api/operations

Demo: /api/operations/demo
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Production operations readiness

/api/operations/readiness

Demo: /api/operations/readiness/demo
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Advisor issue queue

/api/advisor/issue-queue

Demo: /api/advisor/demo/issue-queue
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Advisor handoff readiness aggregate

/api/advisor/readiness

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Privacy and data controls

/api/privacy/controls

Demo: /api/privacy/demo/controls
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Privacy and data-control readiness aggregate

/api/privacy/readiness

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Auth bootstrap and account receipts

/api/auth/bootstrap

Production-only route
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Auth session and tenant scope probe

/api/auth/session

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-saferead
ready
Advisor invite management

/api/advisor/invites

Production-only route
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Advisor invite acceptance

/api/advisor/invites/accept

Production-only route
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Household member inventory and onboarding

/api/household/members

Production-only route
DBSessionTenantStorageAuditDemoSecret-safewrite
ready
Production validation readiness

/api/validation/readiness

Demo: /api/validation/demo/readiness
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Production launch readiness

/api/launch/readiness

Demo: /api/launch/readiness/demo
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Audit packet generation and files

/api/audit-packet

Demo: /api/audit-packet/demo
DBSessionTenantStorageAuditDemoSecret-safeexport
ready
Audit packet artifact request

/api/audit-packet/files

Production-only route
DBSessionTenantStorageAuditDemoSecret-safeexport
ready
Audit packet artifact signed URLs

/api/audit-packet/files/[artifact]

Demo: /api/audit-packet/demo/files/[artifact]
DBSessionTenantStorageAuditDemoSecret-safeexport
ready
Annual closeout and export history readiness

/api/annual-review

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-saferead
ready
Production launch readiness aggregate

/api/launch/readiness

Demo: /api/launch/readiness/demo
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Production launch operations aggregate

/api/launch/operations

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Advanced trust readiness aggregate

/api/trust/readiness

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Jurisdiction module readiness aggregate

/api/jurisdictions/readiness

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready
Paid beta offer readiness

/api/beta/offers

Production-only route
DBSessionTenantStorageAudit optionalDemoSecret-safeaggregate
ready

Phase 6 Evidence

Production service replacement checklist

9/9
ready
Production API namespace beside demo routes

32 production routes are inventoried with explicit demo boundaries and secret-safe responses.

ready
Database-backed dashboard summary

/api/dashboard is database-backed, bearer-session gated, tenant-scoped, and separated from /api/dashboard/demo.

ready
Private evidence upload and download routes

/api/evidence/vault routes cover inventory, signed upload URLs, upload completion, signed downloads, and record-backed downloads through private Storage.

ready
Database-backed ledger and day rows

/api/ledger/days and /api/ledger/corrections cover read rows plus audited correction writes.

ready
Database-backed advisor issue queue

/api/advisor/issue-queue is production-backed, tenant-scoped, audited, and demo-separated.

ready
Database-backed privacy and auth controls

/api/privacy/controls, /api/auth/bootstrap, /api/auth/session, advisor invites, invite acceptance, and household member inventory/onboarding cover the auth cutover boundary.

ready
Database-backed packet generation and export

/api/audit-packet, packet file routes, and /api/annual-review cover export records, private artifact URLs, and annual closeout readiness.

ready
Production readiness endpoint

/api/backend/production-readiness exposes environment, Supabase, route, tenant, storage, audit, demo, and secret-safe evidence.

ready
Tenant RLS policy inventory

Committed Supabase migrations define household isolation policies with authenticated scope, write with-check protection, and live policy inventory smoke coverage.

Auth Cutover

Owner, household, and advisor onboarding readiness

6/7
blocked
Supabase Auth reachable

Supabase Auth must be reachable before any production login or invite acceptance UI is enabled.

ready
Owner bootstrap

/api/auth/bootstrap creates encrypted user, household membership, auth-session, and audit records.

ready
Session and tenant probe

/api/auth/session verifies bearer sessions and returns tenant scope without emails, tokens, or encrypted receipts.

ready
Advisor invite management

/api/advisor/invites creates, updates, and revokes encrypted advisor invites with audit receipts.

ready
Advisor invite acceptance

/api/advisor/invites/accept binds an authenticated advisor to an unexpired invite and records encrypted session receipts.

ready
Household member inventory and onboarding

/api/household/members lets owner/member sessions review household membership and lets owners add encrypted household member profiles and membership records.

ready
Public prototype separation

Public design-review routes remain no-auth and separate from authenticated production account routes.

Account Rollout Plan

Controlled accounts before billing or broad login

1/5

Finish Supabase Auth, owner bootstrap, tenant RLS, and production cockpit evidence before owner login rollout.

Owner controlled account

Owner bootstrap, session probe, tenant access, dashboard, ledger, evidence, privacy, advisor, and packet probes pass without rendering secrets.

owner · /production-app
blocked
Household member access

Owner-scoped household member creation is encrypted, tenant-scoped, audited, and excluded from public review routes.

household · /api/household/members
blocked
Advisor invite access

Advisor invite create, update, revoke, acceptance, queue access, redaction, and audit receipts are verified.

advisor · /api/advisor/invites
blocked
Private evidence and packet files

Private upload, authorized download, signed packet artifacts, cross-household denial, audit events, and retention controls are captured privately.

operations · docs/PRODUCTION_CUTOVER_REHEARSAL.md
blocked
Public demo and design boundary

Homepage, owner command center, design handoff, prototype, sitemap, robots, and llms routes remain no-auth and demo-safe.

public-demo · /
ready

Deferred until after controlled rollout

Billing and checkout, Advisor firm tenancy, Concierge fulfillment automation, Production mobile background uploads

Cutover Rehearsal

Manual evidence required before real user accounts

9/9

Launch remains blocked until every rehearsal item has current private evidence, verifier commands are green, and public demo/design routes remain no-auth.

Private evidence upload

Upload one non-sensitive test evidence file, complete the upload, and confirm the evidence inventory shows the record.

evidence · private evidence location
launch gate
Authorized evidence download

Request a short-lived signed download URL for the test record and confirm the authorized household can access it.

evidence · private evidence location
launch gate
Unauthorized evidence access

Confirm a different household or session cannot read or sign the evidence object.

evidence · private evidence location
launch gate
Audit packet generation

Generate a test packet and confirm manifest, attestation, PDF, and ZIP artifacts are written to private packet storage.

packet · private evidence location
launch gate
Audit packet artifact signing

Request short-lived signed URLs for each packet artifact and confirm the URLs expire according to the configured TTL.

packet · private evidence location
launch gate
Cross-household RLS

Attempt same-table reads and writes from another household and confirm tenant isolation blocks access.

rls · private evidence location
launch gate
Advisor redaction

Confirm an advisor without explicit exact-location permission cannot view exact location or private evidence objects.

advisor · private evidence location
launch gate
Audit events

Confirm platform audit events record auth, advisor, evidence, correction, export, and delete activity.

audit · private evidence location
launch gate
Retention controls

Confirm export and delete requests respect retention review before any deletion confirmation.

retention · private evidence location
launch gate

docs/PRODUCTION_CUTOVER_REHEARSAL.md

No secrets, signed URLs, raw evidence files, exact-location records, database URLs, passwords, tokens, or service-role keys are returned by this endpoint.

Production environment

ready

Required Vercel and Supabase environment values are present and secret-safe.

Keep production variables scoped to the correct Vercel environment.

Production API coverage

ready

Authenticated production API routes exist beside demo routes.

Keep demo routes separate from production routes.

Supabase Auth

blocked

Supabase Auth is not reachable from production readiness checks.

Resolve Supabase Auth reachability before login rollout.

Supabase database contract

blocked

Required tenant-scoped tables are missing or unreachable.

Apply and verify Supabase migrations before production data cutover.

Private storage

blocked

Private storage buckets are missing, public, or unreachable.

Fix private Supabase Storage before real uploads.

Tenant and advisor access

blocked

tenant access blocked; advisor access ready

Resolve tenant or advisor access checks before real accounts.

Privacy and redaction

ready

Exact-location redaction, encrypted sensitive fields, and data controls are represented.

Keep exact location hidden by default in advisor flows.

Production smoke

review

Production smoke should be run against the deployed Vercel URL before cutover.

Run production readiness smoke against the deployed app before real-account rollout.

Demo mode boundary

ready

Public demo/design mode remains separate from authenticated production routes.

Preserve demo mode after login is added.

Billing

deferred

Billing remains deferred; paid-beta packaging can be reviewed without real checkout.

Keep real checkout disabled until paid-beta packaging is approved.

Readiness checks

blocked
ready
Required Vercel environment

11 required environment variable(s) are configured.

ready
Environment URL shape

App, Supabase, and database URL values are well formed.

ready
Preview backend isolation

This deployment is not a Vercel Preview environment.

blocked
Supabase Auth reachability

Supabase readiness check failed before receiving a response.

blocked
Private Supabase Storage

Supabase readiness check failed before receiving a response.

blocked
Supabase Storage RLS policies

Supabase readiness check failed before receiving a response.

blocked
Supabase database contract

Supabase readiness check failed before receiving a response.

blocked
Backend policy records

Supabase readiness check failed before receiving a response.

blocked
Supabase migration history

Supabase readiness check failed before receiving a response.

blocked
Supabase tenant RLS policies

Supabase readiness check failed before receiving a response.

Cutover guardrails

guarded
  • Billing remains deferred until paid-beta checkout is approved.
  • Public demo and design-review routes remain separate from production account routes.
  • Server-only secrets are checked without returning secret values.
  • Exact-location and advisor access boundaries stay part of the launch gate.

Before cutover

Supabase Auth reachability: Supabase readiness check failed before receiving a response.

Private Supabase Storage: Supabase readiness check failed before receiving a response.

Supabase Storage RLS policies: Supabase readiness check failed before receiving a response.

Supabase database contract: Supabase readiness check failed before receiving a response.

Backend policy records: Supabase readiness check failed before receiving a response.

Supabase migration history: Supabase readiness check failed before receiving a response.

Supabase tenant RLS policies: Supabase readiness check failed before receiving a response.

Launch Evidence Manifest

Production smoke and manual evidence index

review

The launch evidence manifest at /api/launch/evidence/manifest exposes evidenceSourceSummary and automatedSmokeEvidence blocks for production promotion. Reviewers should confirm manual evidence buckets, required production smoke surfaces, demo readiness surfaces, live readiness surfaces, secret-policy checks, launch approval boundaries, and evidence-source reconciliation before accepting launch evidence. The launchApprovalChecklist must show external-provider-evidence, live-supabase-smoke, production-readiness-smoke, and manual-cutover-review before real users are enabled.